InsightIdentityMicrosoft 365Conditional Access

Identity is the new perimeter. Most organisations are still defending the old one.

Email runs on identity. Files run on identity. Cloud apps run on identity. Admin portals, remote sessions and line-of-business systems now sit behind it. When that layer is loose, every other control has to compensate. When it is well designed, the rest of the stack becomes easier to secure and operate.

The issue is not whether MFA is enabled. It is whether the identity layer is designed, monitored and operated properly — authentication strength by role, Conditional Access coverage, admin privilege, device trust, non-human identities, session protection and mailbox-side signals.

Old perimeter / identity layer / access decision
ACCESS LOGINMFAPOLICYSIGNAL Identity Layerthe real perimeterMFA QualityConditional AccessDevice and SignalNetwork Perimeterno longer the edgeAUTHAUTHAUTHAUTHAUTH OLD PERIMETER
BoundaryThe login is the boundary
MFAQuality, not presence
PolicyConditional Access as the engine
Quick orientation

Three questions that explain why identity is now the front door

What “identity is the front door” means in practice, why MFA-on is not the same as identity-ready, and what an identity review actually examines.

01

What does “identity is the front door” actually mean?

The login is now where access decisions actually happen. Email, files, line-of-business apps, admin portals, remote sessions and most cloud workflows sit behind identity. When attackers want in, they target the identity layer, not the network edge. When defenders want to control access, the levers are in identity policy, not the firewall.

ThemeThe boundary
02

We have MFA on. Why isn't that enough?

Because MFA presence and identity readiness are different things. Push-based and SMS MFA are still phishable. Legacy authentication can bypass MFA entirely. Stolen tokens can let attackers replay valid sessions without re-authenticating. Per-user MFA leaves admins, executives and finance staff treated the same as everyone else. The MFA tickbox is the starting point; the identity posture determines what an attacker can actually reach.

ThemeMFA quality
03

What does an identity review actually examine?

Six areas: authentication methods by persona, Conditional Access coverage by resource and scenario, admin role design including standing privilege, device trust and session protection, non-human identity hygiene, and monitoring depth across all sign-in log types and mailbox forensics. The output is a current-state map and a prioritised list of work, not another slide deck.

ThemeReview scope
Why identity moved to the front

The old perimeter was the network edge. It is no longer where access decisions are made.

The old perimeter
  • Firewall as the boundary
  • Inside trusted, outside not
  • Worked when apps in data centres, people at desks
  • Decides on where the user is sitting
Identity as the perimeter
  • The login is the security boundary
  • Every access decision evaluated
  • Signals user, device, location, application, risk
  • Reach whatever the identity can reach
User
Device
Location
Application
Risk
Decision

Microsoft Entra ID's Conditional Access engine evaluates user, device, location, application and risk for every access decision.

What MFA-on does not solve

The MFA tickbox is comforting. The identity posture behind it is often not.

Most Australian SME and mid-market environments are not in the position of “we have no security.” They are in the position of “we have Microsoft 365, we turned MFA on, and we assumed identity was handled.” That assumption is the weak point — behind it sit familiar mechanisms that MFA-on-by-default does not solve.

Gap 01 · Phishable MFA methods
The mechanismSMS, voice and push approval are still common defaults. Approval fatigue, prompt bombing and adversary-in-the-middle phishing pages can defeat them.
What it meansPhishing-resistant methods — passkeys, FIDO2 keys, Windows Hello for Business, certificate-based authentication — are different in kind, not just degree.
Gap 02 · Legacy authentication tolerated
The mechanismOlder protocols can sidestep modern MFA entirely. Microsoft has noted that the overwhelming majority of password spray attacks rely on these protocols.
What it meansIf sign-in logs still show legacy authentication, MFA is enforced for some scenarios and bypassed for others.
Gap 03 · Token theft and replay
The mechanismA successful login produces a token. If the token can be stolen and replayed, the attacker does not need to repeat the login.
What it meansToken protection and continuous access evaluation address this directly. Without them, a single phishing success can grant a session that survives elsewhere.
Gap 04 · Per-user MFA instead of Conditional Access
The mechanismPer-user MFA treats every user the same. It does not distinguish admins from finance staff from contractors.
What it meansConditional Access is the policy engine that allows different rules for different personas, scenarios, devices and risk signals. Per-user MFA is no longer the recommended model.
Gap 05 · Mailbox compromise without sign-in alerts
The mechanismThe login often looks legitimate. The compromise shows up later as forwarding rules to unknown addresses, suspicious sending patterns, deleted mail, or contact changes.
What it meansIdentity monitoring that ignores mailbox-side signals misses where the harm actually happens.
Gap 06 · Non-human identities outside policy
The mechanismConditional Access applied to user groups does not always apply to service principals and managed identities. App registrations and stored secrets are routinely outside the identity review scope.
What it meansModern persistence increasingly lives there.

The Australian data. 42% of Category 3 cyber incidents responded to by ASD's ACSC in FY2024-25 involved compromised accounts or credentials (Australian Signals Directorate, Annual Cyber Threat Report 2024-25). “We have MFA” is a true statement that often hides several gaps — the interesting question is what an attacker would actually have to do to walk through.

The current-state map

An identity review is a current-state map of how the identity layer actually operates today.

Not a Microsoft 365 audit and not a vendor sales motion. Scored against a defensible model, with a prioritised list of what to close first — output that supports both leadership decisions and technical remediation.

Authentication
01

Authentication methods by persona

Standard users, admins, finance, executives and external paths each examined against actual authentication strength and allowed methods — not a single tenant-wide statement.

02

Conditional Access coverage and quality

Which policies cover which users, applications and admin roles, where report-only effects have been tested, where legacy authentication is still tolerated, and where gaps exist that nobody has yet noticed.

Privilege and devices
03

Privileged role design

Standing versus eligible access, count of Global Administrators, break-glass account configuration, access review cadence, and Privileged Identity Management posture if licensing allows.

04

Device trust and session protection

Compliant device enforcement, hybrid join state where relevant, device code flow restrictions, token protection scope, and critical event revocation behaviour.

Coverage and response
05

Non-human identity hygiene

App registrations, service principals, user-based service accounts, certificate and secret inventory, federation opportunity, and direct Conditional Access applicability.

06

Monitoring and response depth

All sign-in log types in scope, audit log export, risky users and risky service principals reviewed, suspicious sending and forwarding patterns visible, and mailbox forensics readiness for the inevitable BEC investigation.

Identity operated as infrastructure

Each layer addresses something MFA presence alone does not.

A defensible identity posture is not a single product purchase. It is a set of design and operating choices that together raise the cost of compromise — each achievable for a mid-sized Australian organisation running Microsoft 365 with the right licence tier and the right operating discipline.

None of these are exotic. Most are achievable inside Microsoft 365 when licensing, configuration and operating ownership are aligned. The hard part is rarely the technology. It is treating identity like infrastructure rather than like an admin portal nobody visits.

Operate
Authentication strength by persona
Phishing-resistant MFA for privileged roles; strength applied where it matters most.
Conditional Access as the policy engine
Designed deliberately, staged in report-only mode, then enforced.
Admin privilege reduced and time-boxed
Just-in-time elevation, minimal standing roles, tested break-glass exclusions.
Device trust integrated with access
Compliant or hybrid-joined devices for sensitive actions; tokens bound to the device.
Non-human identity in scope
Service accounts, app registrations, workload identities and stored secrets reviewed.
Monitoring across all sign-in types
Interactive, non-interactive, service principals — with mailbox signals surfaced fast.
The Inlight IT view

Identity is now one of the core operating layers in modern IT.

The Inlight IT view is that identity controls access to email, files, cloud applications, admin portals, remote sessions and increasingly the systems that used to sit behind the network edge. When identity is loose, the rest of the security stack has to work harder. The gap is rarely that an organisation has done nothing — it is in the operating detail: which MFA methods are allowed, whether Conditional Access is enforced properly, how admin privilege is granted, whether service principals are reviewed, and whether mailbox and sign-in signals are monitored together. This is engineering work, not a tenant checklist.

Identity is now the perimeter. It deserves to be operated like one.

01

Treat identity as infrastructure

02

Design and enforce Conditional Access

03

Reduce standing admin privilege

04

Monitor sign-in and mailbox signals together

Cyber Security Review

Identity is the front door. Find out where it is unlocked.

Review authentication, privileged access and sign-in controls across Microsoft 365.

Discuss your cyber security position